-
Notifications
You must be signed in to change notification settings - Fork 16
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
xss issues and no escaping of HTML content etc. #38
Comments
Where's XSS currently (without server-side rendering)? |
Maybe I was wrong thinking without server rendring. I was thinking about your virtual text, but actually you are creating a text node directly, so there are no issues there. However, you should consider cast to string, and number and For dealing with dates, you should use @dfilatov A better solution would be like this if performance are important
|
@dfilatov So you know. I'm not a developer. My work and expert field are bug and issue tracking, and performance. How to optimize code to gain the best performance. |
@rickardjanson Thank you a lot for your issues. I don't keep up with them all right now. But I'll look at them careful as soon as possible. |
@dfilatov Not a problem :) But to make things clear. You aim to build the fastest virtual DOM implementation? If so, I like challenges. So I can try to use my expertise if you want to help you along the road. There is a lot of micto optimizing people don't even think or know about :) I sent you an email this morning with a code suggestion regarding how to do it with prototype to get the rendring down from yours Just note that I'm not a Github person. I'm here to see how other people do things. I have a 38 hours job - yes you are reading correctly ( it feels like it at least ) offline. But when I got time I will help you out. |
I sent you the email again just now. And NOW I have to go offline and do my work for some hours. Bye! |
Currently there's no such issue. |
There are XSS issues in your code, and no escaping of HTML content etc. But will probably become a bigger problem for you when you do server side rendring.
The text was updated successfully, but these errors were encountered: